← All News
03.09.2026 21:29 gamblinginsider 1 views
Calls for IT Security Audits Following Marshall Gramm Incident

In the aftermath of Marshall Gramm's suspension from the Horseracing Integrity and Safety Authority (HISA), two prominent organizations within the horse racing industry have reached out to federal regulators. They are requesting an independent assessment of HISA, particularly regarding its ability to safeguard confidential information on its online platform.

Bill Carstanjen, CEO of Churchill Downs Inc., expressed concerns in a letter addressed to Andrew Ferguson, the Federal Trade Commission (FTC) chairman, and FTC commissioner Mark Meador. He highlighted that recent developments have exposed significant deficiencies and alarming indicators in HISA's governance.

This letter was sent just four days after Gramm accepted a provisional suspension due to allegations that he accessed health data from HISA's database concerning horses he did not own. He reportedly used this information to acquire horses entered in claiming races and participated in various handicapping contests during this time.

After HISA publicly announced the charges on August 17, Gramm returned his contest winnings and stated his intention to relinquish any purse money earned as an owner, along with any horses he claimed. Furthermore, he is required to divest all other racehorses he owns before they can participate in races or official workouts.

Three days prior to Churchill Downs' correspondence, the National Horsemen’s Benevolent and Protective Association (NHBPA), alongside the North America Association of Racetrack Veterinarians and the U.S. Trotting Association, also contacted Ferguson to request an inquiry into HISA's data security measures.

The NHBPA represents over 30,000 owners and trainers nationwide, many of whom have horses registered in the HISA portal. Their letter, signed by NHBPA CEO Eric Hamelback and leaders from the other associations, urged the FTC to mandate independent audits of HISA's cybersecurity and financial records before approving the authority's upcoming budget.

According to the NHBPA letter, HISA allocated $10.7 million for its IT systems in 2025, a significant increase from the $6.1 million budgeted in 2023. The horsemen and veterinarians believe this funding should enable the authority to adequately secure its online portal.

HISA grants access to approved veterinarians to update health records of horses, and state regulators may also gain access. Horse owners must register, with their access limited to their own horses.

The issue gained attention in mid-June when customized performance charts containing restricted information surfaced on social media. Initially, HISA CEO Lisa Lazarus denied that the data originated from the authority's database.

In a statement regarding the charges on August 17, Gramm acknowledged that he unintentionally accessed data for all horses through his HISA portal account and expressed regret for not disclosing this sooner. HISA contends that Gramm utilized an automated method to extract records over a six-week span, with the volume of data retrieved resembling that of approved veterinarians.

The horsemen's letter raised a critical question: “How could an individual using his own login credentials repeatedly obtain a vast dataset of confidential veterinary information outside the scope of his legitimate access, automate the process, and allegedly continue this for approximately six weeks without HISA detecting the activity?”

The NHBPA has previously opposed the establishment of HISA. The Horseracing Integrity and Safety Act, enacted nearly six years ago, created HISA as a private entity under the FTC to standardize the sport's regulations.

Horsemen from various states have filed lawsuits in federal court, asserting that the authority is unconstitutional.

Tags
HISA Marshall Gramm horse racing data security IT audits
Share:

Bring Your Project to Life

Contact us today for your success in the iGaming world.

Contact Us